SANS Internet Storm Center's Daily Network Security News Podcast

Network Security News Summary for Thursday March 30th, 2023


Listen Later

Multi Stream Extraction; 3CX Compromise; MSFT Defender False Positive; Extracting Multiple Streams From OLE Files https://isc.sans.edu/diary/Extracting%20Multiple%20Streams%20From%20OLE%20Files/29688 3CXDesktop App Compromise https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/ Microsoft Defender False Positives https://twitter.com/MSFT365Status/status/1641048649525260289 https://admin.microsoft.com/Adminportal/Home?ref=/servicehealth/:/alerts/DZ534539 (requires login) Active Exploitation of IBM Aspera Faspex CVE-2022-47986 https://www.rapid7.com/blog/post/2023/03/28/etr-active-exploitation-of-ibm-aspera-faspex-cve-2022-47986/ QNAP Patch for sudo vulnerablity https://www.qnap.com/en/security-advisory/qsa-23-11 keywords: qnap; aspera; ibm; faspex; microsoft; false positives; 3cx; voip; supply chain; excel; multiple stream;
...more
View all episodesView all episodes
Download on the App Store

SANS Internet Storm Center's Daily Network Security News PodcastBy Johannes B. Ullrich